CVE-2023-47251
MEDIUMmprivacy-tools < 2.0.406g - Authenticated Path Traversal via VNC Print Function
Title source: llmDescription
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the VNC service, which automatically transfers them to the connected VNC client's filesystem.
References (5)
Core 5
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html
Third Party Advisory
https://sec-consult.com/en/vulnerability-lab/advisories/index.html
Third Party Advisory
https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-m-privacy-tightgate-pro/
Exploit, Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2023/Nov/13
Scores
CVSS v3
6.5
EPSS
0.0173
EPSS Percentile
74.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (2)
m-privacy/mprivacy-tools
< 2.0.406g
m-privacy/tightgatevnc
< 4.1.2-1
Published
Nov 22, 2023
Tracked Since
Feb 18, 2026